package com.liming.web.controller;

import java.io.IOException;
import java.sql.Timestamp;
import java.text.SimpleDateFormat;
import java.util.Date;

import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

import com.liming.domain.Book;
import com.liming.domain.User;
import com.liming.service.impl.BookServiceImpl;
import com.liming.utils.DBUtils;

public class BuyItemServlet extends HttpServlet {

	public void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
			String id=request.getParameter("id");
			String num=request.getParameter("num");
			BookServiceImpl service=new BookServiceImpl();
			
			Book book=service.findBook(id);
			
			
			
			User user=(User)request.getSession().getAttribute("user");
			String s=book.getbId()+new SimpleDateFormat("yyyyMMddHHmmsss").format(new Date());
			
			if(user!=null){
				
				String sql="insert into Buylist values( \'"+user.getUsername()+"\',\'"+book.getbId()+"\',\'"+s+"\',"+(book.getbFixprice()*Integer.parseInt(num))+","+num+",\'"+new Timestamp(new Date().getTime())+"\')";
				
				System.out.println(sql);
				DBUtils.insert(sql);
			}
			String sql="delete from Pickbooks where U_username=\'"+user.getUsername()+"\' and B_id=\'"+id+"\'";
			System.out.println(sql);
			DBUtils.delete(sql);
			response.sendRedirect(request.getContextPath()+"/servlet/BuyCarfoUI");
	}

	public void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		doGet(request, response);

	}

}
